StackRadar

CVE-2024-47554

High

Advisory

Published 3 Oct 2024In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.013
69th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
355
of 17,781 indexed, latest versions
Container images
389
deployed by those charts
Fix available
1 of 1
affected package

Apache Commons IO: Possible denial of service attack on untrusted input to XmlStreamReader

Carried by container images the latest versions of 355 of 17,781 indexed charts deploy, on 389 images.

Affected packageAffected versionsFixed inImages
commons-iomaven2.0, 2.1, 2.2, 2.3+10 more2.14.0389
OSV records
GHSA-78wr-2p64-hpwj

Charts affected

355 by stars
ChartLatestAffected imagesRadar Score
keycloakaccount-serviceVerified publisher18.4.51 of 2See more

keycloak account-service 18.4.5

1 of the 2 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:17.0.1-legacy68f9f38c8f30
commons-io@2.8.0
2.14.0

Open the chart page →

7,713
airbyte-cronairbyteVerified publisher0.40.371 of 1See more

airbyte-cron airbyte 0.40.37

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
airbyte/cron:0.40.17caf4f551c546
commons-io@2.7
2.14.0

Open the chart page →

1,413
akto-ai-guardrails-v2akto0.3.01 of 6See more

akto-ai-guardrails-v2 akto 0.3.0

1 of the 6 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
aktosecurity/data-ingestion-service:1.4.946ed5bcb04b2
commons-io@2.6
2.14.0

Open the chart page →

9,321
akto-testing-db-layerakto1.42.161 of 2See more

akto-testing-db-layer akto 1.42.16

1 of the 2 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/akto-api-security-testing-db-layer:1.59.3_local8cdcb7e83f9f
commons-io@2.6
2.14.0

Open the chart page →

5,489
data-ingestion-serviceakto0.1.61 of 1See more

data-ingestion-service akto 0.1.6

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
aktosecurity/data-ingestion-servicedigest-pinned213aded7adc5
commons-io@2.6
2.14.0

Open the chart page →

3,442
amorphieamorphie0.1.22 of 18See more

amorphie amorphie 0.1.2

2 of the 18 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
hazelcast/hazelcast:5.3.18fe26efde8e1
commons-io@2.11.0
2.14.0
hazelcast/management-center:5.3.2f9d34300d330
commons-io@2.7
2.14.0

Open the chart page →

28,131
omada-controllerandrelote-k8sVerified publisher4.5.01 of 1See more

omada-controller andrelote-k8s 4.5.0

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
mbentley/omada-controller:4.3f4e682274bed
commons-io@2.2
2.14.0

Open the chart page →

11,553
apache-iotdbapache-iotdb-single-nodeVerified publisher0.1.01 of 1See more

apache-iotdb apache-iotdb-single-node 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
apache/iotdb:0.11.28647309f95d1
commons-io@2.5
2.14.0

Open the chart page →

5,277
inbox-server-distributedappscodeVerified publisher2025.12.251 of 4See more

inbox-server-distributed appscode 2025.12.25

1 of the 4 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
opensearchproject/opensearch:2.1.04254021a8c71
commons-io@2.7
2.14.0

Open the chart page →

15,573
james-komposeappscodeVerified publisher0.1.02 of 4See more

james-kompose appscode 0.1.0

2 of the 4 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
opensearchproject/opensearch:2.1.04254021a8c71
commons-io@2.7
2.14.0
ghcr.io/appscode/inbox-server:MailetGroup4a2824296412
commons-io@2.8.0
2.14.0

Open the chart page →

16,975
chart-app-vidapp-vid-chartVerified publisher0.0.71 of 2See more

chart-app-vid app-vid-chart 0.0.7

1 of the 2 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
fimperato/sparkvid-api:1.0.5-RELEASE604012b77841
commons-io@2.4
2.14.0

Open the chart page →

8,866
automatedconfigurationassist-iot-automated-configuration1.0.01 of 5See more

automatedconfiguration assist-iot-automated-configuration 1.0.0

1 of the 5 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
assistiot/automated_configuration:latest23f195a7a26a
commons-io@2.6
2.14.0

Open the chart page →

14,728
idmassist-iot-identity-manager0.1.01 of 2See more

idm assist-iot-identity-manager 0.1.0

1 of the 2 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
assistiot/identity-manager_kc:latest0df4b4fa899a
commons-io@2.8.0
2.14.0

Open the chart page →

13,352
sdn-controllerassist-iot-sdn-controller2.4.01 of 1See more

sdn-controller assist-iot-sdn-controller 2.4.0

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
assistiot/sdn_controller:2.4.0ea254b6d8a31
commons-io@2.6
2.14.0

Open the chart page →

7,936
dashboard-pui9assist-iot-tactile-dashboard0.2.01 of 3See more

dashboard-pui9 assist-iot-tactile-dashboard 0.2.0

1 of the 3 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
assistiot/tacticle_dashboard:api-lateste4414cb72dc4
commons-io@2.11.0
2.14.0

Open the chart page →

4,145
asya-playgroundasya1.1.31 of 1See more

asya-playground asya 1.1.3

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
localstack/localstack:3.19d278167f2b7
commons-io@2.11.0
2.14.0

Open the chart page →

9,412
axelor-open-suiteaxelor-open-suiteVerified publisher7.2.581 of 2See more

axelor-open-suite axelor-open-suite 7.2.58

1 of the 2 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
pmoscode/axelor-open-suite:v7.2.57a58f4d762f5c
commons-io@2.8.0
2.14.0

Open the chart page →

9,722
opendistro-esbeeinventor1.15.11 of 3See more

opendistro-es beeinventor 1.15.1

1 of the 3 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch:1.13.32acfa1dcc5f8
commons-io@2.3
2.14.0

Open the chart page →

5,806
blackduck-alertblackduck8.4.01 of 4See more

blackduck-alert blackduck 8.4.0

1 of the 4 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
blackducksoftware/blackduck-alert:8.4.090cca32de2cc
commons-io@2.8.0
2.14.0

Open the chart page →

4,292
bluerange-serverbluerangeOfficialVerified publisher1.3.11 of 1See more

bluerange-server bluerange 1.3.1

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
bluerange/bluerange:26.1.307c8f73b55df
commons-io@2.8.0
2.14.0

Open the chart page →

1,816
geoservercamptocamp20.0.35 of 12See more

geoserver camptocamp2 0.0.3

5 of the 12 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
geoservercloud/geoserver-cloud-rest:1.0-RC25dc0c93a1710
commons-io@2.10.0
2.14.0
geoservercloud/geoserver-cloud-wcs:1.0-RC247ae1bdb4bcc
commons-io@2.10.0
2.14.0
geoservercloud/geoserver-cloud-webui:1.0-RC228c3e5a8c5a3
commons-io@2.10.0
2.14.0
geoservercloud/geoserver-cloud-wfs:1.0-RC28c70ee06d5ab
commons-io@2.10.0
2.14.0
geoservercloud/geoserver-cloud-wms:1.0-RC242775ba6a4da
commons-io@2.10.0
2.14.0

Open the chart page →

88,335
opensearch-singlenodecaptnbpVerified publisher1.0.91 of 2See more

opensearch-singlenode captnbp 1.0.9

1 of the 2 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
opensearchproject/opensearch:2.15.01963b3ece46d
commons-io@2.8.0
2.14.0

Open the chart page →

1,073
rpc-routerchronicleVerified publisher0.2.91 of 1See more

rpc-router chronicle 0.2.9

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
drpcorg/dshackle:0.54.08858fae1859d
commons-io@2.6
2.14.0

Open the chart page →

6,447
gocdcloudnativeapp1.9.22 of 2See more

gocd cloudnativeapp 1.9.2

2 of the 2 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
gocd/gocd-agent-alpine-3.9:v19.3.053588bd3221f
commons-io@2.6
2.14.0
gocd/gocd-server:v19.3.02da45cb09d57
commons-io@2.6
2.14.0

Open the chart page →

9,144
metabasecloudnativeapp0.5.01 of 1See more

metabase cloudnativeapp 0.5.0

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
metabase/metabase:v0.31.2ffb2dccacefc
commons-io@2.5
2.14.0

Open the chart page →

4,601
neo4jcloudnativeapp1.0.01 of 1See more

neo4j cloudnativeapp 1.0.0

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
library/neo4j:3.4.5-enterprisea1ba477fa412
commons-io@2.6
2.14.0

Open the chart page →

2,837
prestocloudnativeapp0.1.11 of 1See more

presto cloudnativeapp 0.1.1

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
bivas/presto:0.19605545994f806
commons-io@2.4
2.14.0

Open the chart page →

7,226
riemanncloudnativeapp0.1.21 of 1See more

riemann cloudnativeapp 0.1.2

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
raykrueger/riemann:0.2.14c8baf3de57bb
commons-io@2.5
2.14.0

Open the chart page →

6,497
rundeckcloudnativeapp0.1.01 of 2See more

rundeck cloudnativeapp 0.1.0

1 of the 2 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
rundeck/rundeck:3.0.16b13e8059ad72
commons-io@2.2
2.14.0

Open the chart page →

23,665
spark-history-servercloudnativeapp1.0.01 of 3See more

spark-history-server cloudnativeapp 1.0.0

1 of the 3 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
lightbend/spark-history-server:2.4.00bedf37f428a
commons-io@2.4
2.14.0

Open the chart page →

14,066
unificloudnativeapp0.4.21 of 1See more

unifi cloudnativeapp 0.4.2

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
jacobalberty/unifi:5.10.19c409924e2463
commons-io@2.6
2.14.0

Open the chart page →

22,442
dependency-trackcnieg3.0.81 of 2See more

dependency-track cnieg 3.0.8

1 of the 2 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
dependencytrack/apiserver:4.6.3485ac0952c02
commons-io@2.11.0
2.14.0

Open the chart page →

2,503
pulsarcnieg1.0.82 of 2See more

pulsar cnieg 1.0.8

2 of the 2 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
apachepulsar/pulsar:2.6.14db6ff0b4045
commons-io@2.5
2.14.0
apachepulsar/pulsar-manager:v0.1.0b341ef76a852
commons-io@2.5
2.14.0

Open the chart page →

16,860
sumo-besu-genesisconsensys0.1.751 of 1See more

sumo-besu-genesis consensys 0.1.75

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
hyperledger/besu:22.4-openjdk-latesta674d35eec9a
commons-io@2.11.0
2.14.0

Open the chart page →

7,963
sumo-besu-nodeconsensys0.1.751 of 4See more

sumo-besu-node consensys 0.1.75

1 of the 4 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
hyperledger/besu:22.4-openjdk-latesta674d35eec9a
commons-io@2.11.0
2.14.0

Open the chart page →

7,963
cp-helm-chartscp-helm-charts0.6.12 of 8See more

cp-helm-charts cp-helm-charts 0.6.1

2 of the 8 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
confluentinc/cp-kafka-connect:6.1.04bc70a83ca6f
commons-io@2.5
2.14.0
confluentinc/cp-ksqldb-server:6.1.0ee403d5b9090
commons-io@2.5
2.14.0

Open the chart page →

58,857
ldapd4nVerified publisher0.1.01 of 1See more

ldap d4n 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
dwimberger/ldap-ad-it:latest0c636e55eb82
commons-io@2.4
2.14.0

Open the chart page →

1,657
apache-ranger-admindata-platform-stableVerified publisher0.2.01 of 2See more

apache-ranger-admin data-platform-stable 0.2.0

1 of the 2 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
egdsandaru/apache-ranger-admin:1.0.0681baa1926f4
commons-io@2.5
2.14.0

Open the chart page →

8,245
deployhubdeployhubVerified publisher10.0.4151 of 11See more

deployhub deployhub 10.0.415

1 of the 11 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
quay.io/deployhub/ms-ui:svccat-v11.0.815-g717581f5dedbc31e6f
commons-io@2.8.0
2.14.0

Open the chart page →

11,160
spark-standalonedmwm-bigdataVerified publisher0.1.01 of 2See more

spark-standalone dmwm-bigdata 0.1.0

1 of the 2 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
gradiant/spark:2.4.4-python-alpine97657d56e927
commons-io@2.4
2.14.0

Open the chart page →

6,147
api-postsdniel0.9.11 of 1See more

api-posts dniel 0.9.1

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
dniel/api-posts:master45a667852f2a
commons-io@2.6
2.14.0

Open the chart page →

8,986
forwardauthdniel2.0.131 of 1See more

forwardauth dniel 2.0.13

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
dniel/forwardauth:latestf67129ea1c64
commons-io@2.6
2.14.0

Open the chart page →

4,592
drogue-cloud-coredrogue-iotVerified publisher0.7.111 of 22See more

drogue-cloud-core drogue-iot 0.7.11

1 of the 22 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0054ef67eb7da
commons-io@2.7
2.14.0

Open the chart page →

55,666
drogue-cloud-twindrogue-iotVerified publisher0.7.111 of 8See more

drogue-cloud-twin drogue-iot 0.7.11

1 of the 8 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0054ef67eb7da
commons-io@2.7
2.14.0

Open the chart page →

6,915
amundsenduyet1.1.01 of 7See more

amundsen duyet 1.1.0

1 of the 7 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
library/neo4j:3.3.0d4eaa8484246
commons-io@2.4
2.14.0

Open the chart page →

11,174
spark-shuffleduyet0.2.01 of 1See more

spark-shuffle duyet 0.2.0

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
snappydatainc/spark-shuffle:v2.2.0-kubernetes-0.5.1fd4b2070466f
commons-io@2.4
2.14.0

Open the chart page →

5,639
rundeckdwardu-helm-charts0.3.41 of 2See more

rundeck dwardu-helm-charts 0.3.4

1 of the 2 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
rundeck/rundeck:3.2.74d64fe56f767
commons-io@2.2
2.14.0

Open the chart page →

19,802
dshackledysnixVerified publisher0.1.11 of 2See more

dshackle dysnix 0.1.1

1 of the 2 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
emeraldpay/dshackle:0.12ac2a4bc66ab6
commons-io@2.6
2.14.0

Open the chart page →

2,237
entrypoint-balancereclipse-aeriosVerified publisher1.3.01 of 1See more

entrypoint-balancer eclipse-aerios 1.3.0

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
eclipseaerios/entrypoint-balancer:1.3.043cd999a008d
commons-io@2.11.0
2.14.0

Open the chart page →

2,512
mintakaeclipse-aeriosVerified publisher1.0.01 of 2See more

mintaka eclipse-aerios 1.0.0

1 of the 2 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
fiware/mintaka:0.7.092a3c5cf43c0
commons-io@2.6
2.14.0

Open the chart page →

11,482

Container images carrying it

389 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
binhex/arch-nzbhydra2:3.1.0-1-01fb8952921ab6
commons-io@2.6
2.14.0
1
bitnamilegacy/elasticsearch:8.12.215d4647fd491
commons-io@2.11.0
2.14.0
1
bitnamilegacy/elasticsearch:8.12.1-debian-11-r29cfd2df1294d
commons-io@2.11.0
2.14.0
1
bitnamilegacy/keycloak:20.0.5cb04e49e6eb1
commons-io@2.7
2.14.0
1
bitnamilegacy/zookeeper:3.8.1-debian-11-r6dba59d740e13
commons-io@2.11.0
2.14.0
1
bivas/presto:0.19605545994f806
commons-io@2.4
2.14.0
1
blackducksoftware/blackduck-alert:8.4.090cca32de2cc
commons-io@2.8.0
2.14.0
1
bluerange/bluerange:26.1.307c8f73b55df
commons-io@2.8.0
2.14.0
1
codetogether/codetogether:latest4348c8a38752
commons-io@2.7
2.14.0
1
confluentinc/cp-kafka:7.4.4c0224a1adf7a
commons-io@2.11.0
2.14.0
1
confluentinc/cp-kafka-connect:6.1.04bc70a83ca6f
commons-io@2.5
2.14.0
1
confluentinc/cp-ksqldb-server:7.6.08ec46c27982f
commons-io@2.11.0
2.14.0
1
confluentinc/cp-ksqldb-server:6.1.0ee403d5b9090
commons-io@2.5
2.14.0
1
craigwillis/c2metadata-bd:latestae317d7e4724
commons-io@2.6
2.14.0
1
datamate/seafile-professional:11.0.202dd66b722464
commons-io@2.11.0
2.14.0
1
datappeal/hive-metastore:lateste38c085a3567
commons-io@2.5
2.14.0
1
dbanda/livy:0.80ca125e68e53
commons-io@2.5
2.14.0
1
dbanda/spark:2.4.6d0e6367876ae
commons-io@2.5
2.14.0
1
deltaio/delta-sharing-server:0.2.08b75118187c5
commons-io@2.4
2.14.0
1
dniel/api-posts:master45a667852f2a
commons-io@2.6
2.14.0
1
dniel/forwardauth:latestf67129ea1c64
commons-io@2.6
2.14.0
1
dremio/dremio-oss:24.1.080ed2e3b7c43
commons-io@2.11.0
2.14.0
1
drpcorg/dshackle:0.54.08858fae1859d
commons-io@2.6
2.14.0
1
duck1123/dinsro:latest9568c5961d5d
commons-io@2.10.0
2.14.0
1
duck1123/me.untethr.nostr-relay:0.2.1119fc5d4cbfb
commons-io@2.11.0
2.14.0
1
dwimberger/ldap-ad-it:latest0c636e55eb82
commons-io@2.4
2.14.0
1
easypi/openrefine:3.7.0d2950a36a576
commons-io@2.11.0
2.14.0
1
eclipseaerios/entrypoint-balancer:1.3.043cd999a008d
commons-io@2.11.0
2.14.0
1
egdsandaru/apache-ranger-admin:1.0.0681baa1926f4
commons-io@2.5
2.14.0
1
elastictranscoder/media:627e21dc963ab3858c6b
commons-io@2.7
2.14.0
1
elastictranscoder/media-storage:f6d861a026208b8c2359
commons-io@2.7
2.14.0
1
elastictranscoder/transcoder-handler:627e21dc5b75d19e2733
commons-io@2.7
2.14.0
1
emcniece/dockeryourxyzzy:404eccbccc15c
commons-io@2.6
2.14.0
1
emeraldpay/dshackle:0.14.0126f0ae0b388
commons-io@2.6
2.14.0
1
emeraldpay/dshackle:0.12ac2a4bc66ab6
commons-io@2.6
2.14.0
1
expediagroup/pitchfork:1.314f2cf61e7de9
commons-io@2.7
2.14.0
1
farberg/apache-knox-docker:1.6.14b4a22487394
commons-io@2.8.0
2.14.0
1
fimperato/sparkvid-api:1.0.5-RELEASE604012b77841
commons-io@2.4
2.14.0
1
fiware/mintaka:0.7.092a3c5cf43c0
commons-io@2.6
2.14.0
1
fiware/mintaka:latestefc6793388cc
commons-io@2.8.0
2.14.0
1
flofree/base-project:2.1.16b6486c5f81e
commons-io@2.4
2.14.0
1
folioci/mod-codex-ekb:latest235a3fa4adc9
commons-io@2.11.0
2.14.0
1
folioci/mod-codex-inventory:latest6d53ed758fd1
commons-io@2.11.0
2.14.0
1
folioci/mod-codex-mux:latestd4138abfd30d
commons-io@2.11.0
2.14.0
1
folioci/mod-copycat:latest1513fad2b799
commons-io@2.11.0
2.14.0
1
folioci/mod-data-import-converter-storage:latest3028f333778f
commons-io@2.11.0
2.14.0
1
folioci/mod-marccat:latest1b57d690d568
commons-io@2.1
2.14.0
1
fonoster/routr:1.0.0-rc52ca65af17cbc
commons-io@2.2
2.14.0
1
frankescobar/allure-docker-service:2.21.08a4d7e9308de
commons-io@2.11.0
2.14.0
1
frankescobar/allure-docker-service:2.19.0cafa03b94dac
commons-io@2.11.0
2.14.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.